# AQUILA - Google Workspace Integration

<div class="SCXW11705193 BCX8" id="bkmrk-"><div class="OutlineElement Ltr SCXW11705193 BCX8">  
</div></div>### <span style="color: rgb(53, 152, 219);">Google Workspace Integration Overview</span>

<span style="color: rgb(0, 0, 0);">The Google Workspace integration collects and parses data from various **<span style="color: rgb(132, 63, 161);">[Google Workspace audit reports APIs ](https://developers.google.com/admin-sdk/reports/reference/rest)</span>**</span><span style="color: rgb(0, 0, 0);"><span class="TextRun Highlight SCXW11705193 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">using a service account authorized via the **Admin SDK API**.</span></span></span>

### <span style="color: rgb(53, 152, 219);"><span class="TextRun Highlight SCXW11705193 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">Requirements</span></span><span class="EOP SCXW11705193 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span></span>

<span style="color: rgb(0, 0, 0);">To ingest data from the Google Reports API, the following must be completed:</span>

- <span style="color: rgb(0, 0, 0);">An **administrator account** in Google Workspace.</span>
- <span style="color: rgb(0, 0, 0);">Enable the **Admin SDK API** in GCP.</span>
- <span style="color: rgb(0, 0, 0);">Create and configure a **Service Account**.</span>
- <span style="color: rgb(0, 0, 0);">Enable **Domain-Wide Delegation** for the service account.</span>
- <span style="color: rgb(0, 0, 0);">Configure the **OAuth Consent Screen**.</span>

### <span style="color: rgb(53, 152, 219);">1.Enable Admin SDK API</span>

<span style="color: rgb(0, 0, 0);">Our AQUILA agent will eventually use our GCP service account, which uses the [Workspace Admin SDK](https://developers.google.com/admin-sdk) to interact with the GW admin console REST API, therefore it needs to be enabled in GCP. To keep your mind at ease, we will only be enabling read access to the Reports API for this admin SDK.</span>

<span style="color: rgb(0, 0, 0);">Complete the following steps:</span>

- <span style="color: rgb(0, 0, 0);">Select the Google Cloud navigation menu &gt; **APIs &amp; Services** &gt; **Enabled APIs &amp; Services**</span>
- <span style="color: rgb(0, 0, 0);">Search and enable “**Admin SDK API**” from the **API library page**</span>

<span style="color: rgb(0, 0, 0);">When finished, you will have enabled the Admin SDK API within your project, where your service account will have access to pull data from GW.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/xj1heCkKEmxFRvw0-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/xj1heCkKEmxFRvw0-image.png)

### <span style="color: rgb(0, 0, 0);"><span class="absolute -top-32" id="bkmrk--2"></span><span style="color: rgb(53, 152, 219);">2.Configure OAuth Consent Screen</span></span>

<span style="color: rgb(0, 0, 0);">We next need to set up the [OAuth consent screen](https://developers.google.com/workspace/guides/configure-oauth-consent) for our service account and application when they create API requests to GW, as it will include the necessary authorization token.</span>

<span style="color: rgb(0, 0, 0);">Complete the following steps:</span>

1. <span style="color: rgb(0, 0, 0);">Select the Google Cloud navigation menu &gt; **APIs &amp; Services** &gt; **Enabled APIs &amp; Services** &gt; **OAuth Consent Screen**</span>
2. <span style="color: rgb(0, 0, 0);">User Type &gt; Internal &gt; Create</span>
3. <span style="color: rgb(0, 0, 0);">Fill out the following information in subsequent steps</span>
4. <span style="color: rgb(0, 0, 0);">App name: </span>
5. <span style="color: rgb(0, 0, 0);">User support email: </span>
6. <span style="color: rgb(0, 0, 0);">Authorized domains: </span>
7. <span style="color: rgb(0, 0, 0);">Developer contact information:</span>
8. <span style="color: rgb(0, 0, 0);">Save and Continue</span>
9. <span style="color: rgb(0, 0, 0);">Save and Continue</span>
10. <span style="color: rgb(0, 0, 0);">Back to Dashboard</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/Wb5ntsAc3GFF6vzC-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/Wb5ntsAc3GFF6vzC-image.png)

<span style="color: rgb(0, 0, 0);">When finished, we will now have a registered application using OAuth 2.0 for authorization and the consent screen information set. Please note, the default token request limit for this app daily is 10,000 but can be increased. We recommend setting your agent’s pull rate to every 10 minutes which should not come close to this reaching this threshold. Setting the agent’s pull rate will be done at a later step.</span>

### <span style="color: rgb(0, 0, 0);"><span class="absolute -top-32" id="bkmrk--4"></span><span style="color: rgb(53, 152, 219);">3.Create a Service Account</span></span>

<span style="color: rgb(0, 0, 0);">For the AQUILA agent to ingest data from GW, we will need to create a [service account](https://cloud.google.com/iam/docs/service-accounts) for the agent to use. This account is meant for non-human applications, allowing it to access resources in GW via the Admin SDK API we enabled earlier.</span>

<span style="color: rgb(0, 0, 0);">To create a service account, do the following:</span>

1. <span style="color: rgb(0, 0, 0);">Select the navigation menu in Google Cloud &gt; **APIs &amp; Services** &gt; **Credentials** &gt; **Create Credentials** &gt; **Service Account**</span>
2. <span style="color: rgb(0, 0, 0);">Enter the following information:</span>
3. <span style="color: rgb(0, 0, 0);">Service account name: a</span>
4. <span style="color: rgb(0, 0, 0);">Service account ID: </span>
5. <span style="color: rgb(0, 0, 0);">Leave the rest blank and continue</span>
6. <span style="color: rgb(0, 0, 0);">Select your new **Service Account** &gt; **Keys** &gt; **Add Key** &gt; **Create New Key** &gt; **JSON**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/idneceejFxjgkglB-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/idneceejFxjgkglB-image.png)

<span style="color: rgb(0, 0, 0);">By default, the Owner role will be applied to this service account based on inheritance from the project, feel free to scope permissions tighter as best seen fit. When finished, you should have a service account, credentials for this service account in a JSON file saved to your host. We will enter this information during our GW integration setup.</span>

### <span style="color: rgb(0, 0, 0);"><span class="absolute -top-32" id="bkmrk--6"></span><span style="color: rgb(53, 152, 219);">4.Enable Domain-Wide Delegation</span></span>

<span style="color: rgb(0, 0, 0);">Our service account will need [domain-wide delegation](https://developers.google.com/admin-sdk/directory/v1/guides/delegation) of permissions to access APIs that reach outside of GCP and into GW. The important data necessary for this has already been established in earlier steps where we need an API key, service account and OAuth client ID.</span>

<span style="color: rgb(0, 0, 0);">To enable domain-wide delegation for your service account, do the following:</span>

1. <span style="color: rgb(0, 0, 0);">In your GW Admin Console select &gt; **Navigation Menu** &gt; **Security** &gt; **Access and data control** &gt; **API controls**</span>
2. <span style="color: rgb(0, 0, 0);">Select **Manage Domain Wide Delegation** &gt; **Add New**</span>
3. <span style="color: rgb(0, 0, 0);">Client ID: OAuth ID from Service Account in GCP</span>
4. <span style="color: rgb(0, 0, 0);">Google Cloud Console &gt; **IAM &amp; Admin** &gt; **Service Accounts** &gt; **OAuth 2 Client ID** (copy to clipboard)</span>
5. <span style="color: rgb(0, 0, 0);">**OAuth Scopes**: [https://www.googleapis.com/auth/admin.reports.audit.readonly](https://www.googleapis.com/auth/admin.reports.audit.readonly)</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/iME4GsGjhRnpwodR-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/iME4GsGjhRnpwodR-image.png)

<span style="color: rgb(0, 0, 0);">Our service account in GCP only needs access to admin.reports.audit.readonly to access GW [Audit Reports](https://developers.google.com/admin-sdk/reports/v1/get-start/overview) where these are converted into ECS documents.</span>

<span style="color: rgb(0, 0, 0);">If you made it this far, CONGRATULATIONS you are doing outstanding! Your GW and GCP environments are now set up and finished. At this point you are almost done.</span>

<p class="callout info">**<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">CyTech Support</span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">:</span></span><span class="EOP SCXW11705193 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span></span>**</p>

<div class="SCXW11705193 BCX8" id="bkmrk-jwt-file---specifies"><div class="ListContainerWrapper SCXW11705193 BCX8">- <span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" style="color: rgb(0, 0, 0);" xml:lang="EN-US">**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">Delegated Account - </span>**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">the email of the administrator account, and not the email of the ServiceAccount.</span></span>
- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">Jwt</span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop"> JSON</span>** </span><span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">- The JSON credentials file downloaded from GCP. </span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">Raw contents of the JWT file. Useful when hosting a file along with the agent is not possible. NOTE: Please use either JWT File or JWT JSON parameter</span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">.</span></span><span class="EOP SCXW11705193 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span></span>

</div></div>  *Reference link: [https://www.elastic.co/security-labs/google-workspace-attack-surface-part-two](https://www.elastic.co/security-labs/google-workspace-attack-surface-part-two)*

*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact our support at </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"> </span>*

<div class="SCXW11705193 BCX8" id="bkmrk-delegated-account---"></div>